Vulnerabilities/

seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization

Severity:
High

Description

A type confusion issue in seroval.fromJSON() allowed attacker-controlled JSON input to cause Promise control nodes to operate on values from the general deserialization reference table without first verifying that those values were genuine internal promise resolver records.

Recommendation

Update the seroval package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
seroval
Anything's wrong? Let us know Last updated on July 24, 2026